I am running Splunk Enterprise 8.0.6 and have HadoopDataRoll configured, using Hadoop 3.2.1 with Java 1.8.0_282-b08. I have a virtual index configured to archive an index to AWS S3. The HadoopData...
I have an indexer cluster with a replication factor of 3. If I were to implement HadoopDataRoll, would only one copy of each event be archived to Hadoop at freeze time, or would all three bucket c...
...opied as per below doc.
https://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Automatearchiving
Im planning to use HadoopDataRoll to send the splunk index data to Hadoop for longer R...
Hi,
I'm searching for the documentation for the new 6.5 hadoopdataroll feature, and unable to find it. Can someone point me to it? Or where it's setup within Splunk? Nothing obvious stands o...
Documentation says Archive indexer data to meet your data retention policies without using valuable indexer space.
How exactly does this help Splunk indexers? Does Hadoop has more compression r...
We are getting a bunch of the following errors as our AWS EC2 indexers try to archive buckets to S3 with HadoopDataRoll.
How can we fix them or will they get retried and we can ignore them, if s...
We use the Splunk HadoopDataRoll to move our frozen data over to our Hadoop cluster. The writing of the data to HDFS seems to work pretty well, but the searching of it through Splunk d...
I am trying to configure HadoopDataRoll to archive data to a S3-compatible data store.
I can confirm that I can access the data store via s3cmd (https://s3tools.org/usage) as well as Hadoop o...
Recently I have archived buckets of _internal index(older than 90 days) from one site of splunk indexers to Hadoop cluster using https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/A...
While running a query via EMR on a bucket archived to s3 with hadoopdataroll, I got the following error:
[hadoop] [ip-192-168-4-184] Streamed search execute failed because: Error reading c...